Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

shadowx

Members
  • Posts

    230
  • Joined

  • Last visited

Everything posted by shadowx

  1. How can they force you to take holiday if the site is shut.... I would argue that they can't. Surely, if you turn up at the door fully prepared for work and no-one is there to open the site then you can't be forced to take that day as holiday? It would be like forcing all shop employees to take ever sunday as holiday even though the shop is shut every sunday, thus you could advertise 52 days of holiday a year then force staff to use it every sunday and in effect they get no holiday?... either that or I am misreading something here...
  2. I've taken the plunge, signed up for the OU earlier in the year for a degree with honours in computer science, the reason... (dont shoot me) to teach I was wondering if anyone has done an OU course or a computer science degree in the last couple of years and any advice they might have? One thing I am thinking is that module 3 (in 3-4 years anyhoo) is a project of some description. I am hoping against all hope that I can do something like a proposal for a network infrastructure redesign and all the considerations, costs and blah de blah that go with it to present it as a research project and get good marks. Does that sound reasonably likely? Alternatively something programmed in PHP but that's probably less likely... I am hoping I can do something along the lines of network redesign since we redid all our backend last year and hopefully in the next few years we will be re-doing all of our cabling and infrastructure so I can keep a copy of all the documentation and hopefully I'll be sitting pretty
  3. We use RDWeb Access here, as much as I hate microsoft it is the only part of our new windows backend that I actually think is good. The staff can access it from any computer running internet explorer basically, they go to the URL (Or click the shortcut if using the school issued laptop) login with their AD details and they get presented with a webpage with an icon for every program that their user group is assigned, usually all the word processing stuff and SIMS. They just click what they want and wait 30 seconds and, for example, Word will open on their machine but it is actually a remote version of word. It isn't a remote desktop it is a remote App, so they get all the policies and settings that they get in school plus when they open/save they see their school drives but they are working on their home desktop. We also put a remote desktop icon on the list of apps so if they want a full blown desktop they can click that and it will log them in to a full remote session. Have a look at Windows remote App, it's actually pretty good. Works out of the box on windows 7, with xp you may need to manually download Remote Desktop Client 7 (I tell staff to google RDP7) and you're sorted. The only requirements on the server side are to obviously have RD Web Access installed (which is a paid for product I believe) have the correct CALs and then put your remote box in the DMZ or port forward it correctly. To use SSL you will need a certificate which you can either purchase or distribute the relevant CA certificate on a disc/pre-install it on the laptops so you don't get security warnings. No complaints so far! It also means that SIMS etc... doesn't have to be installed on the ICT workstations, when they do staff training they just log on to a student machine, open up the remote access page and click on SIMs which is nice! And if their laptop/home PC breaks they can use any windows machine in the world.
  4. You can (in theory, I accept no responsibility!) set up the new domain controller during school time, this will then automatically sync the data, I would then wait a day or two to make sure the new server is stable (having two DCs is better than one anyway!) then once everything checks out leave it until as late as possible and send around an email a day before to tell staff to log out before 4pm (or whenever you like) then just shut the old server down. This should then force the new server to act as the sole DC, give it a week or so and if everything still works as expected you can reboot the old server, demote it so that it cleanly removes itself and job done! I wouldn't install SIMS or SQL on the same machine though... that's far too many fragile, fragile eggs in one very unstable basket! Use the old server as your SQL/SIMS server, that's my advice! Can't help with that side of things though.
  5. shadowx

    Old PCs

    As a matter of course we remove the hard drives once machines are headed out, either before we put them into storage here (usually in the basement which has no stairs, just a ladder ) or before they go off. This year I am tempted to reclaim some of the old IT machines, they are reasonable spec but we will see. As a nixxer those machines are absolutely perfect for a decent spec home machine. If not they will go off for "recycling" which, despite whatever guarantees you get you can never be sure what really happens to them... Personally I'd rather see them imaged with edubuntu and sent to either local primary schools or to third world countries. Edubuntu is perfect for education it's only bureaucracy that keeps us all on windows.
  6. 500px sounds good, if only I could actually upload photos to it... that would be, well, nice really... Noobs. Flickr is frankly great, I have a pro account and let's be honest, if you are srs about photography then £12 a year or whatever it works out to is absolutely nothing... without trying to sound big that's less than 0.5% of the price of my camera stuff, and even for a more sane person it's a tiny tiny price to pay compared to what any of us would throw away in a camera shop and for that price you get the ability to sell images directly, for thousands upon thousands of people to see them (if you're good, unlike me ) and if you are a little socialite then you can be social too! I am interested by 500px though I have to admit, so I will send them an email to get them to sort their upload out so I can give it a try, cheers for the heads up on that one. PS google Picasa severely compresses and restricts the size of your images so it's really not worth it, flickr doesnt.
  7. North Korea's guy was probably taken out back and shot after that... Perhaps it is that I am too unintelligent to watch and understand the complexities of football Slightly on topic (in my own sort of way...) Morality is not universal. As a bit of a trekkie (Well, if Voyager counts ) I think of the day when we do meet ETs and see their societies and alliances and what not at which point we have a MASSIVE question to ask ourselves, is it right for us to push our morals and laws on to remote civilizations? Just because we view something as wrong (IE oppression) they may see us as being wrong (IE sexual promiscuity). I completely oppose states like N Korea, Burma, China but that's because I have been taught to oppose them. I think the olympics should welcome all nations provided they abide by the rules which should include things like no prejudice, segregation, inhumane treatment etc.. of their own athletes or anyone else in the host country, abiding by all the local laws and ensuring that the athletes aren't under duress or blackmail etc... and of course equality in that no-one, provided they qualify for the sport, should be denied the opportunity due to race, religion, sex etc...Unless their sport is football, then they should all be denied. As for golf.. God help us... Golf is even more tedious that foozbell. What next? Chess? (Surprise me, go on...)
  8. Dear god no... PLEASE don't use sharepoint... We use a "VLE" built on sharepoint and honestly I couldn't tell you what side of that is worse, SP or the VLE... Sharepoint is pure vile... Anyone, and I mean literally anyone with any snippet knowledge about web design or the web in general could tell that sharepoint is not a solution it is just another problem. It's a non-web technology build on web technologies and accessed through a browser. It is an absolute nightmare to modify (and by modify I mean install mods such as office integration, or email integration, or editors, or templates, or themes. Each time it requires going onto the server itself and using VBS through powershell to install, restart, install, restart, restart again, enable, restart... It's endless. Once installed the theme then doesnt work or what you thought would get rid of the ribbon or modify it to actually work as a website just don't do what you thought owing to the fact that sharepoint cannot and never will be a website (Despite being coded in HTML, JS, CSS and ASP, running on IIS and being used via a browser). It is not suitable for ANYTHING! Get yourself a LAMP server and then find a FREE php share documents server system. Point that system straight to your drives as they stand and you are done. There is no need to use sharepoint to host your drives. I know you can but why would you? Why would you trust an IIS server running sharepoint to provide the critical data on which your school relies on 5 days a week, 7 hours a day?! Better to have the drives and the mapping handled by dedicated (or semi-dedicated) AD and file servers. Sharepoint can then look at those to provide seamless access at home. NOT the other way around! You would be much better to look at either making a system yourself and putting it onto a HTML front end or finding a free PHP system to do it for you (Or if you have to, buying into a cheaper, simpler system for handling documents or even having one coded for you) Sharepoint is an absolute disaster, it really is.
  9. And double check the disc is good, just sayin'... did you burn it yourself? If so test it in another machine to make sure it is set as a boot disc. Should be, but I've never considered burning discs much of a science...
  10. McDonalds aren't participating... Oh! You mean athletes as opposed to legally and morally questionable companies gaining explicit and exclusive promotional rights to the detriment of small individuals and limited companies effectively producing a monopoly effect in the exclusion zones which the law is unwilling and legally unable to challenge due to the Olympic acts and laws passed as part of the contract to host the games in the first place... Silly me! Not to mention sports such as football being "Olympic" despite the fact they have nothing to do with the Olympics at all, the modern perversion of a once superb tradition that brought together the many corners of the world for a celebration of the sporting and artistic traditions and skills from the corners of the globe has instead replaced such skills and arts with football. One of the most popular and yet vulgar and boring activities one could possibly watch. How they manage to find something in football to fight over still astounds me, in fact I can't even find anything in football that can keep me sleeping let alone excite me enough to smack someone in the mouth. But alas perhaps my intelligence (and obviously wit) are far above that required to enjoy the sport of football. !TEAM GB!
  11. Why does he keep unplugging it? What purpose does it serve for him to unplug it? Surely once logged on the GPOs remain in effect preventing admin access and he shouldn't have a local login account? If he has local login rights take those away for starters, if he has found a way around GPOs and uses it regularly block his user account under your UAP which (presumably) states that students and staff are not allowed to circumvent the protections and systems in place to gain unauthorised access and keep it blocked until you can find a reliable way of preventing it. Stack overflow has this: command line - How to check if ping responded or not in a batch file - Stack Overflow It's a setup for batch files that check a ping result, obviously rather then just setting an error state force a shutdown with: shutdown -t 0 -r -f (windows XP, not 100% sure about vista/7) When he complains tell him not to do and slam the door in his face! If he wants IT support then he HAS to abide by the AUP and other "rules" for the system, he can't have the best of both words, he either abides by the rules and gets IT support or breaks them and deals with the problems himself.
  12. These jokes are getting a bit terminal now....
  13. I might have to Bash a few heads together to get some sense outta you lot! And yet no-one got my "location" reference.... either it's not funny or you guys are slow
  14. Right boss, im off down the pub, have fun doing all that work Though I hate the pub, it's not linux-y enough for me!
  15. That's what I needed to know! Now it (almost) makes sense, it's still bad design from microsoft but now I understand why clustering isn't a great option so thanks for that. The thing is, Microsoft don't always make the best software so it makes sense they don't always provide the best instructions either... I have no doubt whatsoever of your indelible competence but one solution does not always fit all and so far in my experience a tailored solution is ALWAYS better than a generic solution that follows one set of instructions.
  16. This is true, provided that the server is brought back online before the lease expires. If the leases expire before the server comes back presumably the machines will indeed throw their IPs away and seek a new one? Or will they realise they can't get a response and just hold on to the IP? We can look at this although at the moment we think trying to route iSCSI data from two different, logically and physically separated, SANS through a two virtual hosts and then into a virtual server could prove a headache. I can't agree or disagree with this, I see no actual reason that clustering file services and the DHCP disk would break DC replication other than Microsoft says so?... What effects can the clustering possible have on the DC functions of the servers?! For all intensive purposes they are separate entities, their only link is in the fact that if C1 goes down while holding DHCP and, let's say the file service "Staff Share" then C2 will detect the failure and load it's instance of Staff Share and the DHCP disk, in the process keeping the DHCP leases and status and allowing reconnects back to Staff Share, including the ability (it would seem anyway) to resume existing file operations such as copies/deletes etc... I don't see how that simple migration can affect the DC functions at all, I understand the fact that if the server is overwhelmed it can fail to respond to the quorum sensing which can then trigger a failover but our servers are not that heavily loaded, if that became an issue in the future then naturally we can look at it. As I said before, this isn't any form of "I am better than you" it's just that I don't understand why people follow the status quo as I just don't understand the potential pitfalls. I am more than happy to redesign the backend if I can understand why I am doing it.
  17. Really?! It would make me more certain that I'm following the right path! If I had my way we would still have a pure linux network with high availability clustering, 100% malware resistance and increased security and stability but the school wanted sharepoint so here we are! I understand that the AD is resilient in that it replicates but the AD only provides user/computer authentication realistically. It's only one part of network uptime the rest comes from the DNS and DHCP, if any one of those services were to fail then end users have no connectivity. AD and DNS both replicate but DHCP does not, the only way to achieve 100% uptime is to cluster it, or get ridiculous and have 100 DHCP servers each with 1% of the IP records on them and settle for 99% uptime (I know I' being pedantic but it illustrates the point perfectly) I'm confused, what I mean is most of the downsides are irrelevant since they would still exist in a non clustered environment, by clustering I don't see how we increase risk/downtime, all I see are the bonuses from having resilient DHCP and file services? Let's ignore what microsoft says for the time being and focus on what we all actually think/know from experience (which I will openly admit is not a lot in my case, this is my first year working with a microsoft backend), what real world consequences are there for clustering that we need to be aware of? We are more than happy to redesign the servers but only if we are confident it's the route to follow.
  18. Interesting, I'm not saying I disagree with you (well, I am ) but I want to run through a few things, purely so I can learn more about clustering the AD servers and what not, it's not me calling you out or nit picking! 10. Assuming you have no errors, move DHCP back to your new servers (see Balance the load on your DHCP servers by using the 80/20 rule for scopes if you want to balance load) From my understanding from previous research this is simply to put 80% of client IPs on one server and the other 20% on the second? In which case the best I can hope for is loosing 20% of my clients, worst case is 80% whereas currently even with one server offline I can support 100% of my clients with DHCP Also file servers... Currently our AD servers run: AD-DS, DHCP, DNS and file services so with your solution we would then need to build two new file servers on dedicated hardware? I dont want to use just one of anything purely for redundancy... But then with two file servers are we not likely to run into collisions with read/writes if they are both hitting one set of LUNs? With clustering we have only one instance of file services running so there is no chance of a collision but in the event of a node failure that instance is migrated, hence we retain functionality. Before this network we had a Novell system which is of course linux based, under linux the clustering worked perfectly for all these services so it could be that we are looking at things through Linux tinted glasses and need to take a step back, or it could be that we are going against the grain and it will ultimately work as well or better. With no other experience to draw on I can't say which side of the line I'm on but from a logical point of view clustering makes sense...
  19. Go on? Just to clarify when I say the DCs are clustered I mean the fact that the DHCP and Witness disks are cluster resources as are the disks that contain home drives, file shares etc.. They are physically on a SAN but are mounted as a cluster volume on one or the other DC. The actual OS and Active Directory data is stored physically on each set of hardware, if that makes sense? Essentially the cluster is there to support shared files/folders When we were looking into it we couldn't see any downsides to clustering unless we missed something in which case now is a great time to tell me what we missed! If it's a massive oversight we could look at shuffling the AD around a bit. EDIT: Seen your link.... From the list of downsides at least half of those would still apply if you had two separate DCs with no clustering, for example downsides such as "They should point at each other for DNS and if one node goes down the other cant resolve anything" Surely in an unclustered two DC network you hit the same problem? Our servers have two DNS records set, one to the other server and one to themselves so if the other server is down then they hit themselves for DNS. Perhaps I didn't explain it properly in my first post, the AD service is not clustered but the servers themselves sit in a cluster purely to share cluster volumes such as the DHCP disk and the file shares.
  20. Erm...yes? O.o Both servers are clustered, the DHCP file system is a cluster resource between them both they have a cluster ip of xx.xx.xx.10 (respectively each server has xx.1 & xx.2 and xx.3 & xx.4 Thanks for the tip on demoting Controller1 ihaveaproblem. Looking through google it seems we are relatively lucky to have the server operational to a degree, it seems if it was a full OS failure it would be more of a pig to fix. On linux I would just uninstall the services, clear the files and re-install but I know better than that when dealing with windows!
  21. I haven't got anything specific other than to suggest disabling all GPOs except the password reset one and see what happens. Could be another GPO is blocking popups/balloon notifications?
  22. So, the time has come to rebuild Controller1, one of two DCs, it had a software failure months ago so we have been using our second DC to get us by until this summer. The situation is that Controller1 has random software glitches meaning it fails to log people on, fails to authenticate in general, fails to assign and check permissions correctly, fails to resolve DNS sometimes all mostly random. It sits in a failover/load balancing cluster with Controller2 so there is no primary or secondary, they both operate at the same level and sync data between them (when working...) so my basic plan is thus: Check Controller1 for any data we need to keep (local files for whatever reason) Make sure Controller2 has all the FSMO's (Thanks google!) Shutdown Controller1 for the last time then delete meta data from the AD on Controller2 that points to the now dead Controller1 (Again, google) Then start the software rebuild starting with server 2008 R2 and whacking all our services on there (Clustering, DNS, DHCP, AD-DC, Backup etc...) obviously keeping it isolated once I start on DNS/DHCP/AD-DC until I sync it with Controller2 Anything I'm missing? We built the system last year so I have experience in setting up a windows network from scratch but this time I have to worry about not corrupting the existing AD data! We had Novell before this so I wasn't as worried about accidentally deleting/corrupting the data. Once it's rebuilt I will then force a replication from Controller2 to Controller1, do I need to worry about a reverse replication where C2 sees the empty AD database of C1 and says "Ah well I best delete all my data too then!"? I understand (I believe) that I can force a one way replication from a server to the current one (IE if I log on to the empty C1 and force it to replicate FROM C2) but what I don't want is some sort of automatic replication, that would be.... awkward.... I can't use the backup of the server since from what I understand it would likely be older than the default tombstone value of the AD. The backups we have a full system state backups designed to be plastered on top of a new install of the OS in the event of catastrophic failure but I have a feeling using those backups would be just as much of a headache, plus they have a good chance of carrying whatever software glitch caused the problem in the first place. Last question, am I better to use the same name as before or wipe references to that name and call it something else like Controller3? Looks like more work to rename it but knowing windows I think it may be the better option?
  23. shadowx

    Password

    Google OPHCrack, linux based botable CD that can change/reset passwords on windows machines. Works really well with XP, haven't tried Vista/7 though.
  24. This. If you can work out a way of identifying the room in which the laptop is being used you can automatically run a .reg file that re-imports the calibration data for that room. Alternatively make an application/interface that gives the teacher a list of all rooms, they click the room and it runs a reg file and imports the data. Or, my preferred option: Tell them to get on with it! Jesus, calibrating a whiteboard takes about 10 seconds! Although I know one member of SLT here that would need to carry a small set of steps everywhere to reach to the top corners
×
×
  • Create New...